mirror of
https://github.com/Tria-plc/edr-platform.git
synced 2026-08-29 14:08:11 +00:00
Namespaces the OAuth landing path in all three places it exists: the API's
ack controller, both web apps' routes, and the redirect_uri env values.
A bare /callback claimed a generic top-level path in every app for one
provider's redirect.
The API side needed care. The ack controller moves to @Controller
('fayda/callback'), and the global-prefix exclusion has to name that exact
path — setGlobalPrefix's exclude is an exact route match, not a subtree, so
excluding "fayda" would have left /fayda/callback served at
/api/fayda/callback and 404ing at the registered redirect_uri, while
reading as though it covered everything under /fayda. Naming the full path
also keeps /api/fayda/verification/* prefixed, which every client calls.
Also drops a stale comment on the portal's callback route describing the
popup that no longer exists, and records why the route is public: behind
RequireAuth the onboarding gate redirects to /portal before the code+state
exchange can run.
NOT verified at runtime — this changes route registration, so boot the API
and confirm GET /fayda/callback answers un-prefixed and
/api/fayda/verification/start still resolves before relying on it.
Deploying this requires registering the new redirect_uri with eSignet
first; FAYDA_WEB_REDIRECT_URI, FAYDA_PORTAL_REDIRECT_URI and any mobile
client must be updated in step or verification breaks with a redirect_uri
mismatch.
47 lines
1.2 KiB
TypeScript
47 lines
1.2 KiB
TypeScript
import { api as apiClient } from '../auth/http';
|
|
|
|
export interface FaydaStartResponse {
|
|
authorizationUrl: string;
|
|
}
|
|
|
|
export interface FaydaCompleteResult {
|
|
purpose: 'LOGIN' | 'VERIFY';
|
|
verified: boolean;
|
|
fullName?: string;
|
|
email?: string;
|
|
phoneNumber?: string;
|
|
/** ISO yyyy-MM-dd */
|
|
birthdate?: string;
|
|
gender?: string;
|
|
iamUserId?: string;
|
|
userDataSaved?: boolean;
|
|
}
|
|
|
|
/** Message posted from the /fayda/callback popup back to the opener window. */
|
|
export interface FaydaCallbackMessage {
|
|
type: 'fayda-callback';
|
|
code?: string;
|
|
state?: string;
|
|
error?: string;
|
|
errorDescription?: string;
|
|
}
|
|
|
|
export const verifaydaService = {
|
|
/** Returns the eSignet authorize URL to open in a popup. */
|
|
start: () =>
|
|
apiClient
|
|
.post<FaydaStartResponse>('/fayda/verification/start', {
|
|
purpose: 'VERIFY',
|
|
platform: 'WEB',
|
|
})
|
|
.then((r) => r.data),
|
|
|
|
/** Exchange the callback code+state for the verified identity attributes. */
|
|
complete: (code: string, state: string) =>
|
|
apiClient
|
|
.get<FaydaCompleteResult>(
|
|
`/fayda/verification/complete?code=${encodeURIComponent(code)}&state=${encodeURIComponent(state)}`,
|
|
)
|
|
.then((r) => r.data),
|
|
};
|